Receipt & Document Scanner

Privacy Policy

Last updated 1 September 2026 · Applies to the Receipt & Document Scanner iOS app

The short version

1. Who we are and how to reach us

This policy explains how the Receipt & Document Scanner iOS app (“the app”) handles your information. In this policy “we”, “us” and “our” mean the independent developer who publishes and operates the app, listed as its seller on the Apple App Store. We are the data controller for the limited information described below.

Data controller contact

Email: appservice24@yahoo.com

In the app: Settings → Report a Problem

Email is our designated contact channel for every privacy request, including access, correction, export, deletion and objection. We do not operate a call centre or a postal enquiry desk, so email reaches us fastest and creates a record for both of us.

Our registered postal address and the developer's full legal name are available free of charge on request — email us and we will provide them. They are also shown on our App Store listing under the seller details.

2. What stays on your device

By default, the app is a local application. The following are created and stored in the app's private storage on your iPhone, and are not transmitted to us:

Text recognition, document detection, and — when Cloud Extraction is off — field extraction all run on your device using Apple's frameworks. Nothing leaves your iPhone for these operations.

3. Cloud Extraction (optional)

Receipts are difficult to read: thermal paper fades, layouts vary by country, and text is often crumpled or angled. Cloud Extraction is an optional feature that sends a page image to our processing service for a more accurate reading.

You are in control

What is sent, and to whom

When — and only when — you use Cloud Extraction, the app sends the page image and the text your device recognised to our service running on Google Cloud. There, two Google Cloud services process it:

Google processes this data as our service provider under the Google Cloud Data Processing Addendum. Under those terms, Google does not use your content for advertising and does not use it to train its models.

What happens to the image

The image is held only in memory for the seconds it takes to process, and is discarded once the result is returned to your device. We do not write it to any database, file store or backup. We do not keep a copy. We cannot retrieve a receipt you have scanned, because we never had one.

Where it is processed

Our service runs in Google Cloud's us-central1 region in the United States. The language-model step uses Google's global endpoint, so that request may be served by Google infrastructure in another region. If you are in the European Economic Area or the United Kingdom, this means your data may be transferred outside your country; these transfers rely on the Standard Contractual Clauses incorporated into Google's Data Processing Addendum.

4. What we do collect

An anonymous identifier

To operate Cloud Extraction the app signs in anonymously with Firebase Authentication. This creates a random identifier for your app installation. It contains no name, email address or phone number, is not linked to your Apple Account, and is not shared with anyone. Deleting and reinstalling the app produces a new one.

Fair-use counters

To prevent abuse of the service, we store a small record for each day you use Cloud Extraction: the anonymous identifier, the date, and how many pages and extractions were processed. These records contain no image, no receipt content and no extracted field values. They are stored in Google Cloud Firestore and are not readable by any app client.

Subscription status

If you subscribe to Pro, the app sends our service the signed receipt Apple issues for your subscription, so that the service can confirm the subscription is genuine before granting the higher usage limits. We verify Apple's signature and read two things from it: which plan you hold, and that it has not expired or been revoked.

We store the result — whether the installation is Pro or free, and which plan — alongside the anonymous identifier. The signed receipt itself is not stored, and it contains no payment details. Without this step, anyone could claim to be a subscriber and consume the service at our expense.

Diagnostic logs

Our service writes operational logs — a timestamp, the anonymous identifier, page counts, processing token counts and any error codes. These logs are deliberately written so that no image data and no extracted field value ever appears in them. They are held in Google Cloud Logging and are automatically deleted after 30 days.

If you email us

When you contact support we receive your email address and whatever you choose to include. If you use Report a Problem in the app, the message is pre-filled with your app version, device model and iOS version so we can reproduce the issue — you can see and edit the whole message before sending it, and nothing is sent until you tap Send.

5. What we never collect

6. Subscriptions and payment

Pro subscriptions are sold through Apple's In-App Purchase system. Apple processes the payment; we never see your card number, billing address or Apple Account details. The app receives only a signed confirmation from Apple stating whether an active subscription exists and when it renews. That confirmation is passed to our service so it can verify your subscription — see “Subscription status” above for exactly what is checked and what is kept. Apple's handling of your purchase is governed by Apple's Privacy Policy.

7. iCloud backup

Pro subscribers can enable iCloud backup. This stores your receipts and documents in your own private iCloud database, under your Apple Account, encrypted and controlled by Apple. It syncs across your own devices. We have no access to it and cannot read, recover or delete anything in it. Turning it off in iOS Settings stops the sync.

8. Children

The app is a general-purpose business and personal-finance tool. It is not directed at children, and we do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your country). If you believe a child has provided us with personal information, contact us and we will delete it.

9. How long we keep things

DataRetention
Your scans, documents and extracted fieldsOn your device until you delete them or remove the app
Page images sent for Cloud ExtractionNot retained — discarded once processed
Fair-use countersKept for abuse prevention; deleted on request
Subscription status (plan, and whether active)Kept while the installation is in use; deleted on request
The signed subscription receipt itselfNot retained — verified and discarded
Diagnostic logsAutomatically deleted after 30 days
Support emailsKept while needed to resolve your issue, then deleted

10. Deleting your data

11. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete the personal data we hold about you, to object to its processing, and to withdraw consent. Because the app requires no account and we hold almost nothing about you, most of these rights are exercised directly on your device using the controls above. For anything else, email us — we will respond within 30 days.

If you are in the EEA or UK, our legal bases are: performance of a contract (providing the extraction you requested), legitimate interests (keeping the service secure and preventing abuse), and consent (Cloud Extraction, which you opt into and can withdraw at any time). You also have the right to lodge a complaint with your local supervisory authority.

If you are in California, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. We will not discriminate against you for exercising your rights.

12. Security

Data in transit between the app and our service is encrypted with TLS. Data on your device is protected by iOS file-system encryption and your device passcode. Access to our Google Cloud project is restricted and protected with two-factor authentication, and the fair-use counters are configured so that no app client can read or write them directly. No system is perfectly secure, but we keep the amount of your data we hold as close to zero as the feature set allows — which is the strongest protection available.

13. Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how your information is handled, we will tell you in the app before it takes effect. Continuing to use the app after a change means you accept the updated policy.

14. Contact

Questions, requests or complaints about privacy: appservice24@yahoo.com.